navigating-chatgpt-history
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/render-range.pyutilizesimportlib.utilto dynamically load the sibling scriptscripts/render-conversation.pyat runtime. The file path is resolved statically relative to the main script's directory, which is a standard pattern for code sharing within a skill package. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external conversation exports.
- Ingestion points: External data enters the agent context through
scripts/inspect-export.py,scripts/list-conversations.py,scripts/search-conversations.py,scripts/render-conversation.py, andscripts/render-range.py, which read contents from ZIP and JSON archives. - Boundary markers: The skill instructions do not specify any boundary markers or directives for the agent to ignore instructions embedded within the processed chat history.
- Capability inventory: The scripts possess the capability to read local files (the archives) and write output to the file system via user-defined paths (e.g.,
/tmp/orreference/chatgpt/). No network capabilities are present. - Sanitization: The skill extracts text using standard JSON and zip parsing; no specific sanitization or filtering is applied to identify or mitigate embedded instructions within the history content.
Audit Metadata